Email Job Scam: How to Spot Fake Recruitment Emails

Last verified by our editorial team: April 2026

Email is still the third-largest delivery channel for job scams after WhatsApp and Telegram. Scammers send fake recruitment emails impersonating Amazon, Google, Microsoft, FedEx, and dozens of other brands. Sophisticated versions copy real company branding and are hard to spot without checking the domain carefully. This guide covers the four email scam patterns, how to verify any recruitment email in 30 seconds, and what to do if you already clicked a link or shared data.

Quick Answer

Real recruitment emails come from a company domain (e.g., @amazon.com), reference your specific application, never request upfront fees, and link only to the company's official careers page. Any deviation is a scam signal.

Red Flags

  • Sender domain does not match the company's official domain
  • Generic greeting ('Dear Candidate') instead of your name
  • Reply-To address differs from sender name
  • Fee, deposit, or activation payment requested
  • Attachment named 'offer letter' or 'onboarding form' from unfamiliar sender
  • Link goes to a domain different from the sender's domain

Paste the message into the free checker

Pattern 1: The Lookalike Domain

Email comes from an address that looks like a real company but is slightly off: amazon-careers.com, microsoft-jobs.net, google-recruitment.org. The domain is registered by the scammer. Compare the domain to the official company URL character by character. If they do not match exactly, it is a scam.

Pattern 2: The Spoofed Header

The 'From' field shows the real company name but the actual sender is different. Hover over the sender name (or view the email source) to see the real Reply-To address. Mismatched From and Reply-To indicates spoofing. Real recruitment emails have matching From and Reply-To.

Pattern 3: The Phishing Attachment or Link

The email asks you to download an 'offer letter PDF' or 'onboarding form' that contains malware, or links to a fake login page that captures your credentials. Never download attachments or click links until you have verified the sender's authenticity by visiting the company's careers page independently.

Pattern 4: The Compromised Real Account

Rarely, a scammer compromises a real recruiter's email account and sends fake offers from their genuine address. The tell: the email contains links to non-company websites, requests personal data atypically, or has an urgent fee request. Even from a real sender, requests that do not fit normal recruitment patterns are suspicious.

The 30-Second Email Verification

Step 1: Check the domain matches the official company domain exactly. Step 2: Hover over links to see real destinations (they should point to the same company domain). Step 3: Search the role on the company's careers page (type the URL directly, do not click any email link). Step 4: Find the recruiter on LinkedIn and verify they work at the company. Step 5: If anything looks off, forward the email to phishing@<company> (phishing@amazon.com, phishing@microsoft.com, etc.) and delete.

How to Read Email Headers to Detect Spoofing

Most email clients hide the full sender information. To expose spoofing, view the full email headers. In Gmail: click the three-dot menu on the email and select 'Show original'. In Outlook: File → Properties → Internet headers. Look at three fields: 'From' (visible sender), 'Return-Path' (where bounces go), and 'Reply-To' (where your reply is sent). Real recruitment emails have all three matching the company domain. Scams typically have From spoofed but Return-Path or Reply-To pointing to a random Gmail or throwaway address. This 30-second check catches even well-crafted phishing.

Common Phishing Email Subject Lines to Watch For

Scammer subject lines follow recognisable patterns. Urgency: 'Action Required: Verify Your Application', 'Final Notice: Job Offer Expires Today'. Fake success: 'Congratulations! You've Been Selected for the Position', 'Your Interview Has Been Approved'. Brand impersonation: 'Amazon HR: Remote Position Available', 'Google Recruitment: New Opportunity'. Payment prompts: 'Complete Your Onboarding Payment', 'Training Fee Required to Confirm Start Date'. Any subject line that combines a real company name with urgency and a call-to-action should be treated as suspicious until the sender is fully verified through the domain and LinkedIn checks above.

Frequently Asked Questions

How do I check if an email domain is real?

Compare the domain after the @ symbol to the company's official website domain exactly. amazon.com is real; amazon-careers.com is fake. Type the company URL directly in your browser rather than clicking any email link.

Can a real recruiter use a Gmail address?

Rarely. Real corporate recruiters use company email. Some independent contract recruiters use Gmail but always identify themselves clearly with company affiliation, LinkedIn link, and a verifiable phone number that matches the company.

What if the email looks identical to a real company message?

Visual quality is meaningless — scammers copy branding easily. The only reliable checks are the sender domain, the Reply-To address, and independent verification through the company's careers page and LinkedIn.

Should I open an attachment in a recruitment email?

Not until you verify the sender. Malicious PDFs and Word docs install malware. If needed after verification, open only on a device with updated antivirus and never enable macros.

What does 'Reply-To' mean?

Reply-To is the address that actually receives your reply. Scammers can fake the visible sender name but not Reply-To. Mismatch = spoofed email.

How do I report a phishing recruitment email?

Forward to phishing@<company> (phishing@amazon.com, phishing@microsoft.com) if available, report to spam@uce.gov for FTC analysis, and mark as phishing in your email client before deleting.

Can email phishing steal my Amazon or bank credentials?

Yes. Phishing links lead to fake login pages that capture credentials. If you entered credentials, change passwords immediately, enable 2FA, and monitor accounts for unauthorised activity.

Are 'job offer' emails from LinkedIn always safe?

InMail from real recruiters is generally safe. But scammers can send LinkedIn messages from cloned profiles. Verify the sender's profile (tenure, connections, activity) before sharing personal data or clicking links.

Check your job offer now — free, private, no signup